# Horda

> Horda is an AI-powered penetration testing service by NoBuzz. A swarm of autonomous AI agents attacks your systems inside a scope you authorize, and senior penetration testers validate every finding before it reaches your report. A full pentest takes 72 hours; Constant Siege keeps testing against new CVEs and zero-days.

- **Service:** AI-powered penetration testing, sold by NoBuzz to companies in Brazil and the United States.
- **Pentest 72h:** US$ 3,990 / engagement (R$ 19.990). A complete AI-driven penetration test of your scope, with human-validated findings in 72 hours.
- **Constant Siege:** US$ 599 / month (R$ 2.990). Continuous validation against new threats and zero-days: 24 hours of swarm testing every month.
- **What Horda tests:** Web apps & APIs (authentication flows, business logic, injection, access control and API abuse, chained end to end); Cloud & infrastructure (misconfigurations, exposed services, identity and privilege paths across AWS, GCP and Azure); Internal & mobile (lateral movement, internal services, mobile backends and the paths an insider would take).
- **Safety and scope:** Every agent action runs inside a consent-gated, rate-limited scope you authorize. Destructive actions are blocked at the tool boundary. Nothing crosses the walls you set.
- **Human validation and reports:** AI finds more, faster. It also hallucinates. Every Horda finding is reproduced and attested by a senior pentester before it enters your report, with evidence attached. Reports come in English and Brazilian Portuguese, structured for LGPD, ANPD and BACEN requirements, with one fail-closed rule: nothing partial gets published.
- **How an engagement works:** Recon: Agents enumerate domains, services, APIs and identities across your authorized scope and build a shared exploration graph of your attack surface. Attack: Agents plan and execute attack paths the way an adversary would: credential paths, logic flaws, misconfigurations and privilege chains, under rate and blast-radius limits. Validate: Every finding is reproduced, rated and attested by a human reviewer, with the evidence trail attached. Unconfirmed results never reach your report. Report: Executive summary, technical detail, reproduction steps and remediation guidance in English and Portuguese, followed by a retest of what you fixed.

## Docs

- [Horda (English)](https://www.horda.si/): AI penetration testing with human validation: a swarm of AI agents attacks your authorized scope and senior pentesters confirm every finding. Report in 72h.
- [Horda (Português)](https://www.horda.si/pt/): Pentest com IA e validação humana: agentes de IA atacam o seu escopo autorizado e pentesters sêniores confirmam cada achado. Teste de invasão em 72 horas.
- [Full site content in Markdown](https://www.horda.si/llms-full.txt): every section of both editions, including plans, FAQ and sources.

## Contact

- [Start a pentest](https://www.horda.si/start/): pick a plan and send the target and contact details; the request goes to horda@nobuzz.io, and scope and authorization are confirmed before any testing.
- [Talk to Sales (30-minute call)](https://cal.com/nobuzz/30min): talk through scope, plans and authorization with the team.
- [Customer console](https://app.horda.si): where customers follow engagements and findings.

## Optional

- [CrowdStrike analysis of an agentic intrusion campaign (September 2026)](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/): the incident cited in the threat section.
